Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur

CISSP Cyber Training Podcast - CISSP Training Program

Join Shon Gerber on his weekly CISSP Cyber Training podcast, where his extensive 23-year background in cybersecurity shines through. With a rich history spanning corporate sectors, government roles, and academic positions, Shon imparts the essential insights and advice necessary to conquer the CISSP exam. His expertise is not just theoretical; as a CISSP credential holder since 2009, Shon translates his deep understanding into actionable training. Each episode is packed with invaluable security strategies and tips that you can implement right away, giving you an edge in the cybersecurity realm...

Author

Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur

Category

Education

Podcast website

www.cisspcybertraining.com

Latest episode

Jul 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster 06.07.2026

Send us Fan Mail Imagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigation, but it gives us a rare chance to see CISSP Domain 2 asset security in real time, with consequences that go far beyond a typical data breach. I walk through what’s being reported about Social Secu...

CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know 29.06.2026

Send us Fan Mail A vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That’s the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact su...

CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know 22.06.2026

Send us Fan Mail Your endpoint tool can be world class and still get taken out first. That’s the unsettling reality behind a new wave of “EDR killer” capabilities being packaged inside ransomware-as-a-service platforms, where affiliates can plug in advanced evasion without building it themselves. When attackers can blind endpoint detection and response before the ransomware payload runs, the old c...

CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP 15.06.2026

Send us Fan Mail Someone is stealing encrypted data right now and they are not trying to read it today. They are saving it for later, betting that quantum computing will eventually break the encryption that protects it. I dig into the “Harvest Now, Decrypt Later” strategy, why it matters most for long-term confidentiality, and how security leaders can talk about it as a present-day risk instead of...

CCT 356: Supply Chain Attacks Are Exploding in 2026 — Here's What the NCSC Wants You to Do 08.06.2026

Send us Fan Mail Your software is only as trustworthy as the dependencies you quietly inherit and attackers know it. Today I break down the NCSC warning on software supply chain security and why open source package ecosystems have become a high-value target for real-world compromises that spread fast through CI/CD pipelines. I walk through the attack patterns that keep showing up in incidents: mai...

CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes 04.06.2026

Send us Fan Mail The breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to rotate. We start with a real-world Zapier-style scenario and unpack how researchers chained together a harmless-looking code block, an AWS Lambda environment, and a misconfigured IAM role to reach priv...

CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY 01.06.2026

Send us Fan Mail Your firewall can be patched tomorrow, but what about the place your system hides its real secrets today? We start with a timely warning about a serious Fortinet FortiGate vulnerability and why perimeter devices are still a make-or-break control, then we pivot into the deeper layer most people ignore until it’s too late: memory. We walk through CISSP Domain 3.4 by focusing on what...

CCT 353: AI Agent Governance Essentials - CISSP Practice Questions 28.05.2026

Send us Fan Mail AI agents are landing in production faster than most security teams can track them, and the scariest part is how normal they can look. When an autonomous agent runs the same workflow 10,000 times, your SIEM and EDR may see “nothing to worry about” even while the agent quietly drifts outside its intended scope. That is the core AI governance problem we tackle, through the lens of C...

CCT 352: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY 25.05.2026

Send us Fan Mail Your security program can be airtight and still get wrecked by someone else’s breach. We open with a Wired-style reality check: third-party app ecosystems and data brokers collecting location analytics at massive scale, then getting hacked or resold in ways your users never expected. If your organisation issues mobile devices, this is where security awareness, MDM controls, and cl...

CCT351: BitLocker Bypass Reality Check (YellowKey) and CISSP Practice Questions 21.05.2026

Send us Fan Mail BitLocker feels like a safety net until you see how a single bypass can change the whole risk picture. Today we react to the Yellow Key vulnerability (noted in the news and referenced as CVE 2645585) and use it as a practical CISSP training moment: a public proof of concept is available, a vendor patch is not, and the attack hinges on physical access. That mix forces you to think...

CCT 350: Investigation Types Made Simple - CISSP Training (Replay) 18.05.2026

Send us Fan Mail Default passwords are the kind of problem everyone “knows” about and yet they still open doors for attackers every day. We start with a quick reality check on router security and why factory settings, legacy gear, and unmanaged IoT and OT devices can turn a simple misconfiguration into redirect attacks, man-in-the-middle exposure, DDoS headaches, or silent monitoring. If you’re st...

CCT 349: FOXCONN Hack and Domain 7 CISSP Practice Questions 14.05.2026

Send us Fan Mail Eight terabytes of stolen schematics is not just a scary number, it is a reminder that cyber risk becomes business risk fast. We start with the Wired report on the Foxconn ransomware attack and unpack what a claim like that could mean in the real world: intellectual property exposure, supply chain disruption, customer impact, and the uncomfortable truth that recovery is only one p...

CCT Vendor 04: The Practical Realities of Geopolitical Cyber Risk - Next Peak Interview 13.05.2026

Send us Fan Mail Next Peak:    https://nextpeak.net/services/icr/ A regional conflict can spike your cyber risk even if your offices never move and your headcount never changes. That is the uncomfortable reality behind geopolitical cyber risk, and it is why I brought on Helen Lee, Director of Intelligence Cyber Research at NextPeak, to break down how global flashpoints turn into real security prob...

CCT 348: ClaudeBleed - The Hidden Risk In AI Browser Extensions and CISSP Domain 3 11.05.2026

Send us Fan Mail Your browser just became a security boundary you can’t afford to ignore. We start with ClaudeBleed, a vulnerability in the Claude AI Chrome extension that shows how an AI browser agent can be hijacked by another malicious extension, even one with zero special permissions. When an agent can act “as you” inside a trusted environment, the risk jumps from theory to real outcomes like...

CCT 347: AI Poisoning the Quiet Enterprise Threats and CISSP Questions (Domain 1) 07.05.2026

Send us Fan Mail Quiet failures are the ones that scare me most, and enterprise AI creates a brand-new way for them to spread. If a chatbot becomes the “trusted employee” everyone relies on, a slow drip of bad documents, outdated procedures, or deliberately manipulated data can poison decisions for months without a single red flag. We break down what that looks like in real organizations, why it d...

CCT 346: Testing Disaster Recovery Plans and Why BEC Still Works Despite MFA (CISSP Domain 7) 04.05.2026

Send us Fan Mail MFA feels like the finish line until you watch a company wire tens of millions of dollars to an attacker without a single password being stolen. We dig into why business email compromise (BEC) still works even in “secure” environments, because the real target is the decision point: trust, timing, urgency, and authority. When attackers can spoof executives or use deepfake voice and...

CCT 345: Practice CISSP Questions - Domain 8.4 (Replay) 30.04.2026

Send us Fan Mail A single compromised identity can turn your whole environment into a hallway of unlocked doors and cross-domain attacks are built to exploit exactly that. We start with a timely real-world breach theme and use it to explain how adversaries move between endpoints, cloud platforms, and third-party connections by abusing identity and privileged access, not just by running noisy malwa...

CCT 344: Trigona RaaS - CISSP 3.7 Crypto - Board Translation Framework (Segment 3) 27.04.2026

Send us Fan Mail Ransomware actors are getting quieter, faster, and more custom and that should change how you study for the CISSP and how you defend your environment. We start with a quick personal update on a new CISSP Sprint: an eight-week live cohort built to give you structure, accountability, and weekly sessions so you can realistically target exam day without paying boot camp prices. Seats...

CCT 343: Microsoft Defender - CISSP EOL-EOS (Part 2) - Board Translation (Segment 2) 23.04.2026

Send us Fan Mail Three Microsoft Defender zero-days are reportedly being exploited, and that is the kind of headline that tests whether our security program is real or just optimistic. I break down what we know, including BlueHammer (CVE-2026-33825) landing in Patch Tuesday while Red Sun and Undefend were described as still unpatched at the time, and the practical response: update fast, verify cov...

CCT 342: US Govt and Mythos - CISSP EOL-EOS (Part 1) - Board Translation (Segment 1) 20.04.2026

Send us Fan Mail The next wave of AI in cybersecurity is not a theory project, it’s an operational deadline. I open with a timely look at reporting that the White House wants federal agencies to get access to Anthropic’s Claude Mythos, and why that scramble matters for every security team. If Mythos can help uncover vulnerabilities and accelerate exploit development, the same capability that stren...

CCT 341: Deepfake Nudify (Wired) - CISSP Exam Practice Test (Deep Dive) 16.04.2026

Send us Fan Mail AI didn’t just make deepfakes easier. It made targeted sexual abuse scalable. I open with a Wired-reported reality that’s hitting schools worldwide: AI tools that can generate fake nude images from ordinary photos, spread through bots and subscription services, and leave students and families dealing with humiliation, harassment, and real trauma. If you’re a cybersecurity professi...

CCT 340: Anthropic Mythos - Risk Management Concepts (Domain 1.10) 13.04.2026

Send us Fan Mail Check us out at:  https://www.cisspcybertraining.com/ Get access to 360 FREE CISSP Questions:  https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout Get access to my FREE CISSP Self-Study Essentials Videos:  https://www.cisspcybertraining.com/offers/KzBKKouv An AI model that can uncover thousands of zero-days and potentially chain multiple vulnerabilities into an automated e...

CCT 339: Infrastructure Insider - Cyber Career Roadmap - No One is Talking About 09.04.2026

Send us Fan Mail Check us out at:  https://www.cisspcybertraining.com/ Get access to 360 FREE CISSP Questions:  https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout Get access to my FREE CISSP Self-Study Essentials Videos:  https://www.cisspcybertraining.com/offers/KzBKKouv A single disgruntled admin can do more damage with “normal” IT tools than many attackers can with malware, and that re...

CCT 338: LinkedIn Monitoring - Support for Patch and Vulnerability Management (Domain 7) 06.04.2026

Send us Fan Mail Check us out at:  https://www.cisspcybertraining.com/ Get access to 360 FREE CISSP Questions:  https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout Get access to my FREE CISSP Self-Study Essentials Videos:  https://www.cisspcybertraining.com/offers/KzBKKouv LinkedIn might be doing more in your browser than you think. We start with a report dubbing it “BrowserGate” a claim t...

CCT 337: UK Manufacture Attacks - CISSP Deep Dive (Domain 4) 02.04.2026

Send us Fan Mail Check us out at:  https://www.cisspcybertraining.com/ Get access to 360 FREE CISSP Questions:  https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout Get access to my FREE CISSP Self-Study Essentials Videos:  https://www.cisspcybertraining.com/offers/KzBKKouv A ransomware headline is easy to ignore until you realize it can shut down a factory line, break supplier networks, an...

Listen to the CISSP Cyber Training Podcast - CISSP Training Program podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.